Enterprise-wide risk assessment software

An EWRA platform for financial crime risk assessment.

Complete your enterprise-wide financial crime risk assessment (EWRA), also known as a business-wide risk assessment (BWRA), with scoring, evidence, controls and reporting connected as you work. The assessment writes the report as you complete it. Built for payments businesses wherever they operate; legal practices have their own firm-wide framework.

Demo: sample data, no sign-up. See the report it produces.

We have been there

Six months of requirements. Six figures of consultant costs. One spreadsheet already going stale.

We hear the same story: an organisation hires expensive consultants, spends months documenting requirements and receives a complicated Excel workbook that starts going stale as soon as it is delivered. We have been there.

EWRA works out of the box.

Use aggregate information you should already have to hand. Start with a tested framework, configure it yourself and get on with the assessment.

Standalone from day one

Start the assessment.
Skip the implementation project.

EWRA works out of the box. Start with a structured framework and sector-specific questions, configure it for your organisation and enter aggregate information you should already have to hand. No data pipeline or systems build is required.

No lengthy integration programme or consultant-led setup is needed to get started.

The methodology was built by a practitioner, has been used in more than one regulated business and across entities in different countries, and has been refined through independent review and regulatory scrutiny.

  1. Choose your framework. Payments, or legal practice.
  2. Enter aggregate information. Use figures you already hold, with evidence and rationale alongside them.
  3. Review the result. Challenge the assessment and complete sign-off.

Intuitive by design

Pick it up.
Know what to do.

A hammer’s shape tells you where to hold it and which end does the work. Software should offer the same clear cues. That’s affordance: familiar controls, obvious next steps and results you can see.

People who use EWRA have started without training and asked very few questions. The most common comment is that it is easy to use. Their feedback is that it makes a demanding, often unwelcome process feel straightforward to complete.

Visible progress, question by question

One answer. Every relevant view updated.

01 / Answer

Enter the figures you know.

Capture current and prior-year data once, against a structured question and clear rationale.

02 / Understand

See the score change in real time.

Percentage change, calculated score and colour-coded risk signal appear immediately, with the rationale kept visible.

03 / Report

Watch the report write itself.

The result flows into the risk table and overall assessment without a separate reporting step.

One answer. An immediate signal. One less section to assemble later.

01 / Risk domains

Build a complete view of financial crime risk.

Use structured questionnaires across customers, products, geography, channels and emerging risks, covering money laundering, terrorist financing and sanctions. Each response carries its supporting rationale and evidence, so reviewers can follow how the conclusion was reached.

  • Defined factor and domain scoring
  • Guidance held alongside each question
  • Evidence linked to the relevant response
02 / Controls & residual risk

Connect control effectiveness to the risk it changes.

Evaluate control design and operating effectiveness against clear criteria. Rotunda calculates residual risk consistently while preserving the underlying judgements for review.

  • Design and operating effectiveness scores
  • Transparent calculation logic
  • Documented overrides where judgement is required
03 / Sanctions risk assessment

Assess sanctions risk on its own terms.

Run a separate sanctions risk assessment without losing the firm-wide view. Keep sanctions-specific exposure, controls and conclusions distinct from the wider financial crime methodology.

  • Dedicated sanctions factors and questions
  • Separate scoring and governance record
  • Clear output for specialist review
04 / Review & challenge

Give every decision an owner and a record.

Route assessments through preparation, review, second-line challenge and approval. Comments remain attached to the relevant answer, with dates and decisions preserved in the audit trail.

  • Role-based stages and clear ownership
  • Comments resolved in context
  • Time-stamped review and sign-off history
05 / Year-on-year comparison

Explain what changed, not just the latest score.

Compare current and prior assessments side by side. Focus review time on material changes in exposure, controls and residual risk, with the reason recorded.

  • Prior-year responses retained
  • Changed answers and scores highlighted
  • Movement commentary ready for governance packs
06 / Audit trail & reporting

Produce the record senior management needs.

Export a clear report of the methodology, inputs, scoring, challenge and conclusions. Use CSV for further analysis or Markdown with tools approved by your organisation, and retain the audit history.

  • PDF assessment report
  • CSV and Markdown data exports
  • Complete audit trail of edits, reviews and approvals

Sector-specific frameworks

Payments first. Legal practices supported.

A useful assessment shows how the business is exposed, what controls are in place and how the conclusion was reached. Rotunda keeps those elements connected.

EWRA’s payments framework covers merchants and customers, products, geography, channels and emerging risks, with sanctions assessed on its own terms. It has been used across entities in different countries and is not tied to one regulator’s template; you can adjust the framework and record why. Legal practices get a firm-wide risk assessment framework with legal-sector terminology. More sectors coming soon.

EWRA is the assessment itself, not a general GRC platform. If you need workflow across every category of enterprise risk, this is not that tool. If you need a financial crime risk assessment a reviewer can follow, it is.

Your organisation remains responsible for its risk-based judgement and regulatory obligations.

Choosing your platform

What should an EWRA platform help you do?

An enterprise-wide risk assessment platform brings the assessment inputs, risk methodology, controls, review and reporting into one workflow. For financial crime work, the purpose is to explain the business’s exposure, assess the controls and document the risk that remains. A score alone is not the assessment.

Rotunda supports this work for payments businesses and legal practices. Start with aggregate information you already hold, complete the structured questions and see the assessment report develop as you go. You can enter the information directly; a systems integration is not required to get started.

Check the whole assessment, from input to approval

  • Scope and inputs: can you record the entity, assessment period and the customer, product, geographic and channel exposures behind the assessment?
  • Scoring and rationale: can a reviewer understand how the answers produce a score, and why a score has been overridden?
  • Control effectiveness: can you distinguish control design from how the control operates, then explain the residual risk?
  • Review and challenge: are comments, decisions, ownership and approval history kept with the assessment?
  • Reporting and change: can you export the assessment and explain what changed from the previous year?

See these steps in the working demo

The demo uses fictional sample data and needs no sign-up. Follow an assessment through risk questions, controls, review and the generated report. Choose the framework closest to your work.

For the underlying process, read how to do an EWRA or BWRA. For access and current pilot terms, see EWRA pricing.

Practical questions

Before you get started.

What is an EWRA?

An enterprise-wide risk assessment (EWRA), also known as a business-wide risk assessment (BWRA), is a business’s own assessment of its exposure to money laundering, terrorist financing and sanctions risk, the controls it relies on and the risk that remains. Legal practices call the same exercise a firm-wide risk assessment. The label matters less than the scope you record. See the practical guide.

Is a BWRA different from an EWRA?

No. They are two names for the same assessment. The FCA’s 2025 review uses “business-wide”; many firms and international guidance use “enterprise-wide”. Rotunda uses EWRA.

Do you work with payments businesses outside the UK?

Yes. Most of our customers are in the UK, and the framework is not tied to one regulator’s template. It has been used across entities in different countries, and the demo’s fictional group includes a UAE branch and an EU entity. Your organisation applies the requirements of its own regulators; EWRA organises the work and the record.

Do we need training?

Most people start without it. Guidance sits alongside each question, results update as you answer, and the report builds as you go.

Where does AI fit?

Automatic calculations and reporting do the everyday work. Optional AI assistance can help authorised users explore results and draft summaries. Evidence, risk appetite and final judgements remain with your team. CSV and Markdown exports can also be used with tools your organisation approves.

Can we adapt the framework?

Adjust the framework to your organisation’s risk profile, recording the rationale for changes and any score overrides.

Who can access our information?

Detailed assessments are available to authorised users in your organisation. Download your assessment data and reports when needed. Peer benchmarking uses anonymous category-level results, excluding narrative answers, evidence and identifiable firm-level data.

Do we need an integration?

You can enter aggregate information directly. Optional automated feeds are scoped separately under the Integrated option.

Take a closer look at EWRA.

Explore the demonstration environment or arrange a focused walkthrough.